-
Notifications
You must be signed in to change notification settings - Fork 0
fix(OSQUERY-002-2): CU-86akhf8u2 16 review findings across 12 files #98
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
100667d
3e20f5e
da0de83
ceccecd
81b4990
7df5b3b
4bfa7ee
a2f9cff
43a8f51
ed3005b
12ccd02
c4e3194
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -50,6 +50,7 @@ | |
| #include <osquery/utils/info/platform_type.h> | ||
| #include <osquery/utils/info/version.h> | ||
| #include <osquery/utils/pidfile/pidfile.h> | ||
| #include <osquery/utils/status/status.h> | ||
| #include <osquery/utils/system/system.h> | ||
| #include <osquery/utils/system/time.h> | ||
|
|
||
|
|
@@ -92,7 +93,7 @@ enum { | |
| #endif | ||
|
|
||
| // OpenFrame includes | ||
| #include "openframe/openframe_authorization_manager_provider.h" | ||
| #include "openframe/openframe_authorization_manager.h" | ||
| #include "openframe/openframe_encryption_service.h" | ||
| #include "openframe/openframe_token_extractor.h" | ||
| #include "openframe/openframe_token_refresher.h" | ||
|
|
@@ -208,35 +209,32 @@ void initWorkDirectories() { | |
| } | ||
| } | ||
|
|
||
| void initOpenFrame() { | ||
| Status initOpenFrame() { | ||
| VLOG(1) << "OpenFrame mode enabled"; | ||
|
|
||
| // Initialize OpenFrame components if secret is provided | ||
| if (FLAGS_openframe_secret.empty()) { | ||
| LOG(ERROR) << "OpenFrame mode enabled but secret not set"; | ||
| return; | ||
| return Status::failure("OpenFrame mode enabled but secret not set"); | ||
| } | ||
|
|
||
| try { | ||
| // Create openframe token services | ||
| auto encryption_service = std::make_shared<OpenframeEncryptionService>(FLAGS_openframe_secret); | ||
| auto token_extractor = std::make_shared<OpenframeTokenExtractor>(encryption_service, FLAGS_openframe_token_path); | ||
|
|
||
| auto initial_token = token_extractor->extractToken(); | ||
|
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 𦩠π΄ openframe_authorization_manager.cpp is not the file included in init.cpp β OpenframeAuthorizationManagerProvider is used but no such symbol exists Replaced π€ Prompt for AI agentsfix confidence: π΄ 40 low β review closely β react π/π to teach the reviewer |
||
| if (!initial_token.empty()) { | ||
| auto& auth_manager = OpenframeAuthorizationManagerProvider::getInstance(); | ||
| auth_manager.updateToken(initial_token); | ||
| LOG(INFO) << "OpenFrame token extracted successfully"; | ||
| } else { | ||
| LOG(ERROR) << "Failed to get initial token from token file"; | ||
| } | ||
|
|
||
| // Create and start token refresher | ||
| static auto token_refresher = std::make_shared<OpenframeTokenRefresher>(token_extractor); | ||
| token_refresher->start(); | ||
| } catch (const std::exception& e) { | ||
| LOG(ERROR) << "Failed to initialize OpenFrame components: " << e.what(); | ||
| // Create openframe token services | ||
| auto encryption_service = std::make_shared<OpenframeEncryptionService>(FLAGS_openframe_secret); | ||
| auto token_extractor = std::make_shared<OpenframeTokenExtractor>(encryption_service, FLAGS_openframe_token_path); | ||
|
|
||
| auto initial_token = token_extractor->extractToken(); | ||
| if (!initial_token.empty()) { | ||
| auto& auth_manager = OpenframeAuthorizationManager::getInstance(); | ||
| auth_manager.updateToken(initial_token); | ||
| LOG(INFO) << "OpenFrame token extracted successfully"; | ||
| } else { | ||
| return Status::failure("Failed to get initial token from token file"); | ||
| } | ||
|
|
||
| // Create and start token refresher | ||
| static auto token_refresher = std::make_shared<OpenframeTokenRefresher>(token_extractor); | ||
| token_refresher->start(); | ||
|
|
||
| return Status::success(); | ||
| } | ||
|
|
||
| void signalHandler(int num) { | ||
|
|
@@ -258,7 +256,6 @@ void signalHandler(int num) { | |
| bool validateAlarmTimeout(const char* flagname, std::uint64_t value) { | ||
|
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 𦩠π std::cerr used for user-facing validator message instead of LOG()/systemLog only Removed the duplicate π€ Prompt for AI agentsfix confidence: π’ 95 high β react π/π to teach the reviewer |
||
| if (value < 10) { | ||
| osquery::systemLog("Alarm timeout cannot be lower than 10 seconds"); | ||
| std::cerr << "Alarm timeout cannot be lower than 10 seconds" << std::endl; | ||
| return false; | ||
| } | ||
|
|
||
|
|
@@ -459,7 +456,11 @@ Initializer::Initializer(int& argc, | |
|
|
||
| // Initialize OpenFrame authorization manager and token refresher if mode is enabled | ||
| if (FLAGS_openframe_mode) { | ||
| initOpenFrame(); | ||
| auto openframe_status = initOpenFrame(); | ||
| if (!openframe_status.ok()) { | ||
| LOG(ERROR) << "Failed to initialize OpenFrame components: " | ||
| << openframe_status.getMessage(); | ||
| } | ||
| } else { | ||
| VLOG(1) << "OpenFrame mode disabled"; | ||
| } | ||
|
|
@@ -954,3 +955,4 @@ void Initializer::shutdownNow(int retcode) { | |
| _Exit(retcode); | ||
| } | ||
| } // namespace osquery | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -62,6 +62,15 @@ void DistributedRunner::start() { | |
| "Reading distributed queries", read_status, last_read_error); | ||
| logOutcomeChange( | ||
| "Writing distributed query results", write_status, last_write_error); | ||
| } else { | ||
| if (!read_status.ok()) { | ||
| LOG(ERROR) << "Error reading distributed queries: " | ||
| << read_status.getMessage(); | ||
| } | ||
| if (!write_status.ok()) { | ||
| LOG(ERROR) << "Error writing distributed query results: " | ||
| << write_status.getMessage(); | ||
| } | ||
| } | ||
|
|
||
| dist.cleanupExpiredRunningQueries(); | ||
|
Comment on lines
62
to
76
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 𦩠π΄ DistributedRunner::start() silently discards Status failures instead of surfacing them consistently In π€ Prompt for AI agentsfix confidence: π‘ 88 medium β react π/π to teach the reviewer |
||
|
|
@@ -89,3 +98,4 @@ Status startDistributed() { | |
| } | ||
| } | ||
| } // namespace osquery | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -42,7 +42,9 @@ SystemStateTracker::Ref SystemStateTracker::create() { | |
| IProcessContextFactory::Ref process_context_factory; | ||
| auto status = IProcessContextFactory::create(process_context_factory); | ||
| if (!status) { | ||
| throw status; | ||
| LOG(ERROR) << "Failed to create the state tracker: " | ||
| << status.getMessage(); | ||
| return nullptr; | ||
| } | ||
|
|
||
| return create(std::move(process_context_factory)); | ||
|
Comment on lines
42
to
50
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 𦩠π΄ SystemStateTracker::create() and constructor throw Status instead of returning it In π€ Prompt for AI agentsfix confidence: π‘ 65 medium β react π/π to teach the reviewer |
||
|
|
@@ -319,6 +321,8 @@ Status SystemStateTracker::expireProcessContexts(Context& context, | |
| bool exists{false}; | ||
| if (!fs.fileExists(exists, procfs_root.get(), process_id.c_str())) { | ||
| return_error = true; | ||
| ++process_map_it; | ||
| continue; | ||
| } | ||
|
|
||
| if (!exists) { | ||
|
Comment on lines
321
to
328
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 𦩠π expireProcessContexts frees process map entries on any fs.fileExists() failure, not just confirmed non-existence In π€ Prompt for AI agentsfix confidence: π’ 95 high β react π/π to teach the reviewer |
||
|
|
@@ -1357,3 +1361,4 @@ SystemStateTracker::Context SystemStateTracker::getContextCopy() const { | |
| } | ||
|
|
||
| } // namespace osquery | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -25,7 +25,7 @@ EtwController& EtwPublisherBase::EtwEngine() { | |
| } | ||
|
|
||
| Status EtwPublisherBase::run() { | ||
|
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 𦩠π΄ EtwPublisherBase::run() returns Status::failure(0, ...) β zero is treated as success by convention Changed π€ Prompt for AI agentsfix confidence: π’ 95 high β react π/π to teach the reviewer |
||
| return Status::failure(0, | ||
| return Status::failure(1, | ||
| "ETW provider is driven by event callbacks. " | ||
| "A pooling thread is not required."); | ||
| } | ||
|
|
@@ -120,3 +120,4 @@ void EtwPublisherBase::updateHardVolumeWithLogicalDrive(std::string& path) { | |
| } | ||
|
|
||
| } // namespace osquery | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
𦩠π΄ initOpenFrame swallows all initialization failures behind a broad try/catch instead of returning Status
initOpenFrame() in osquery/core/init.cpp changed from
voidwith a bare try/catch(const std::exception&) toStatus initOpenFrame(), removing the try/catch entirely and returning Status::failure()/Status::success() at each error/success path. The call site in the Initializer constructor now captures the returned Status and logs via LOG(ERROR) if !ok(). This makes failures observable to the caller as a Status rather than being silently absorbed. Risk: this assumes OpenframeEncryptionService/OpenframeTokenExtractor constructors no longer throw exceptions that need catching; since I cannot see those headers, if they still throw, an exception could now propagate uncaught out of the Initializer constructor. A complete fix would also update those classes to be noexcept/Status-returning, which is out of scope for this file.π€ Prompt for AI agents
fix confidence: π΄ 55 low β review closely β react π/π to teach the reviewer